{"id":"CLSA-2026-1777944610","summary":"grafana: Fix of CVE-2026-27877","details":"- CVE-2026-27877: fix exposure of direct data-source passwords via public\n  dashboards by limiting frontend settings to data sources actually used by\n  the dashboard\n- Note: upstream test additions in pkg/api/frontendsettings_test.go are not\n  backported. The %check stage only runs the Jest frontend suite (gated on\n  0), so backend Go tests would not be exercised by this\n  build, and the upstream test depends on hs.publicDashboardsService which\n  does not exist in 10.2.6 (the production fix already uses the\n  hs.PublicDashboardsApi.PublicDashboardService adapter for the same reason)","modified":"2026-06-01T00:32:51.106885443Z","published":"2026-05-05T01:30:15Z","upstream":["CVE-2026-27877"],"references":[{"type":"ADVISORY","url":"https://errata.tuxcare.com/els_os/tuxcare9.6esu/CLSA-2026-1777944610.html"}],"affected":[{"package":{"name":"grafana","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/grafana?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.2.6-15.el9_6.tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1777944610.json"}},{"package":{"name":"grafana-selinux","ecosystem":"TuxCare:AlmaLinux:9.6","purl":"pkg:rpm/tuxcare/grafana-selinux?distro=almalinux-9.6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.2.6-15.el9_6.tuxcare.els7"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/almalinux9.6esu/CLSA-2026-1777944610.json"}}],"schema_version":"1.7.5"}